Stack buffer overflow in WAD
FortiOS explicit proxy WAD daemon stack buffer overflow (CVSS 5.1) allows code execution only with Kerberos and SOCKS configured.
Fortinet advisory FG-IR-26-161 describes a stack-based buffer overflow (CWE-121) in the WAD daemon of FortiOS explicit proxy, scored CVSSv3 5.1. Exploitation requires an attacker able to bypass stack protection and ASLR, and the explicit proxy must be configured with Kerberos authentication and SOCKS enabled. If successful, it yields arbitrary code or command execution in the WAD daemon context via crafted sockets. No exploitation is reported in the advisory.
- Stack buffer overflow (CWE-121) in the FortiOS WAD daemon
- Requires Kerberos authentication and SOCKS on the explicit proxy
- Exploit must bypass stack protection and ASLR; CVSSv3 5.1
CVSSv3 Score: 5.1 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS explicit proxy may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled. Revised on 2026-08-12 00:00:00
This source does not provide full text. Read it at fortiguard.fortinet.com.